A payment firm based in London receives a letter from His Majesty's Treasury's Office of Financial Sanctions Implementation. The letter asks for documents relating to a specific counterparty, account records covering a defined period, and written explanations of the firm's screening process. The deadline is short. No allegation of wrongdoing accompanies the request – but the tone is unambiguous. How the firm responds in the next few days will shape every subsequent step in the regulatory relationship.
An information request from OFSI (the Office of Financial Sanctions Implementation, the UK authority responsible for financial-sanctions enforcement and licensing) is a formal regulatory demand carrying statutory force under SAMLA (the Sanctions and Anti-Money Laundering Act 2018, the primary legislative basis for the UK's post-Brexit autonomous sanctions regime). Failure to respond fully and accurately within the stated period can itself constitute a separate breach, independent of whatever prompted the original enquiry. As of early 2026, OFSI's enforcement posture has continued to harden, with an expanding use of civil monetary penalties and monetary penalties for non-compliance.
This guide walks through the process step by step: what triggers an information request, what the statutory obligations require, how to organise a response, where the most common failures occur, and how the UK position compares with analogous demands from OFAC, the EU, and other regimes. Each step is written for a general counsel, compliance officer, or senior manager who needs a clear operational sequence, not a summary of legal principles in the abstract.
Step 1 – Understand what OFSI is asking and why
The first step is to read the request precisely: identify every question, every document category, every named counterparty, and every date range specified. OFSI's information requests arise in several distinct contexts, and the context shapes the response strategy.
OFSI may issue a request because it has received a report – from the firm itself, from another institution, or from a third-party source – that a transaction may involve a designated person or a frozen asset. Alternatively, the request may follow from the firm's own mandatory report of a suspected sanctions breach. In some cases, OFSI issues information requests as part of a wider thematic review of a sector, without any suspicion of a specific breach by the recipient. The practical obligation is identical in all three situations, but the risk profile differs sharply.
Where a request arises from a suspected breach involving your firm, the documents you provide will form part of OFSI's evidence base. Every statement made in the response, every document produced, and every omission will be scrutinised against what OFSI already holds. In our experience, the single most important action at this stage is to preserve all potentially relevant material immediately – including communications, transaction records, and any internal screening or override logs – before any routine deletion cycle runs.
A request arising from a thematic review carries a different but real risk: if the documents disclose an unrelated breach or a gap in your compliance programme, OFSI can and does act on that disclosure. The duty of accuracy is unchanged regardless of which category applies.
Step 2 – Assess your legal obligations and the response window
SAMLA and the relevant thematic sanctions regulations give OFSI the power to require persons to provide information and documents, and to answer questions in writing or in person. These powers apply to any person who OFSI reasonably suspects holds relevant information. The obligation attaches to the recipient of the request regardless of whether that person is the subject of an investigation.
The response deadline is set out in the request itself. It may be expressed in calendar days or as a fixed date. The window is often short and OFSI's practice is not to extend it automatically. In our experience, extension requests are granted only where the firm demonstrates genuine logistical difficulty, provides a partial response by the original deadline, and seeks the extension promptly – not on the day the deadline expires. Waiting until the last day before asking for more time is a pattern OFSI notes adversely.
What must you provide? The obligation is to produce accurate, complete information and documents within the scope of the request. You are not required to produce documents that are subject to legal professional privilege – that is, confidential communications between a lawyer and client made for the dominant purpose of obtaining legal advice. However, privilege must be claimed formally and with care. A blanket claim of privilege over an entire document set, without proper review, will not be accepted and risks drawing further scrutiny.
Importantly, the obligation extends to persons within your group who hold the requested information. If the relevant records are held by a subsidiary, a branch, or a parent entity, you must take reasonable steps to obtain and produce them. This has practical consequences for cross-border groups where records sit in non-UK entities: the UK obligation does not disappear because the data is held offshore.
Step 3 – Organise the internal review and evidence-gathering
A structured internal review, carried out under legal professional privilege where possible, is the foundation of a defensible response. The review has three components: document identification and preservation, factual reconstruction, and privilege review.
Document identification means locating all records that fall within the categories specified by OFSI – not only records that help your case, but all records within scope. Selective production is a serious error. If OFSI discovers later that documents within scope were not produced – even if through administrative oversight – it will treat the omission as relevant to culpability. Assign a specific team member to oversee the collection from each business system, and log what was searched and when.
Factual reconstruction means building a chronological account of the events relevant to the request: what decisions were made, who made them, what information was available at each decision point, and what controls operated. This account will underpin the written narrative that typically accompanies a document production. Inconsistencies between the narrative and the documents are the most frequently cited basis for adverse credibility findings in OFSI enforcement decisions.
Privilege review means identifying which documents are covered by legal professional privilege before they are produced. Communications with external counsel retained for the purpose of this response are almost certainly privileged. Internal documents prepared in anticipation of litigation or regulatory proceedings may also be protected under litigation privilege, though the threshold is higher. Do not produce documents without completing this review.
In our experience, firms that treat the internal review as a compliance formality – rather than as the evidentiary foundation of an enforcement matter – regularly produce responses that create more problems than they resolve. The information request is the moment at which the enforcement pathway is set.
Step 4 – Prepare and submit the written response
The written response itself should be structured around each question or document request in the order OFSI posed them. Do not reorder or consolidate requests. Address each item separately and clearly.
For each question requiring a factual answer, the answer should be accurate, complete, and precisely scoped to what was asked. Volunteering additional information that OFSI did not request is rarely beneficial at the information-request stage; it can introduce new lines of enquiry. Conversely, providing answers so narrow that they are technically accurate but misleading in context is a serious error – OFSI's enforcement guidance makes clear that the accuracy obligation extends to the overall impression created by the response, not only the literal truth of each sentence.
The cover letter should identify the person responsible for the response, confirm the scope of the document review undertaken, explain any gaps in the production (documents outside the firm's control, documents destroyed in the ordinary course before the request, documents subject to a privilege claim), and provide contact details for follow-up. A well-drafted cover letter demonstrates that the response is the product of a considered, methodical process.
Sign off at the appropriate level. For a financial institution, the response should be authorised by the MLRO, the Chief Compliance Officer, or a member of the board – not delegated solely to a junior analyst. OFSI will note who signed the response, and that choice signals the seriousness with which the firm treats the matter.
Consider whether the response creates or confirms the basis for a voluntary self-disclosure (a VSD – a proactive report to OFSI of an apparent breach, made before OFSI formally opens an enforcement investigation). A well-timed and substantive VSD, submitted alongside or shortly after the information request response, is one of the factors OFSI takes into account when determining whether to impose a penalty and at what level. The decision to submit a VSD requires careful analysis; it is not always the right route, and the decision should be taken with counsel.
Step 5 – Manage the process after submission
Submitting the response is not the end of the matter. OFSI may issue follow-up questions, request additional documents, or invite the firm to a meeting. Each of these steps carries the same obligation of accuracy as the original response.
Keep a complete record of everything you produce – a paginated document production log, a copy of the cover letter, and the submission date. If OFSI later asserts that a document was not provided, your log is your defence. Maintain that log throughout the process.
Monitor for any designation updates affecting counterparties named in the request. OFSI may add persons to the consolidated sanctions list during an investigation. If a counterparty that was not listed at the time of the original transaction is subsequently designated, you may acquire new obligations – including fresh reporting duties – that run in parallel with the information-request response process.
Where OFSI's follow-up indicates that the matter is moving toward a formal enforcement investigation, the firm should consider whether it needs to notify its board, its senior managers, or regulators in adjacent sectors. For financial institutions, a concurrent obligation to notify the Prudential Regulation Authority or the Financial Conduct Authority may arise. That notification decision should not be made without legal advice.
How does the OFSI process compare with OFAC and the EU?
Practitioners advising cross-border businesses are often asked how an OFSI information request compares with the equivalent demands from OFAC in the United States or from the relevant national competent authorities under EU sanctions regulations. The comparison matters because a business may face concurrent requests from more than one jurisdiction arising from the same underlying transaction.
Under OFAC, the closest equivalent is a subpoena or a civil investigative demand issued in connection with an enforcement investigation, or the agency's practice of requesting voluntary information submissions in advance of a formal notice of apparent violation. OFAC's enforcement process is more formalised at the pre-penalty stage than OFSI's, and the timelines set out in OFAC's enforcement guidelines are more granular. One important difference is that OFAC's penalty regime operates on a maximum-penalty-per-transaction basis with published figures; OFSI's civil monetary penalty authority is set by reference to a statutory cap. The practical result is that the penalty exposure calculation differs, but both regimes treat the accuracy and completeness of an information submission as a factor that affects penalty determination. OFAC also operates a detailed VSD framework that reduces the applicable penalty base for voluntary disclosures that meet the regulatory standard.
Under the EU sanctions regime, information requests are issued by the relevant national competent authority of each member state – the specific authority varies by jurisdiction. The procedural rules, the rights of the recipient, and the available legal protections (including privilege) differ between member states. Cross-border groups operating in the EU should not assume that the approach taken to a UK OFSI request will transfer directly to a request from a French, German, or Dutch competent authority. The substantive prohibitions may be similar; the procedural context can be substantially different. For an assessment of how EU competent authority requests compare with the UK position in a specific enforcement scenario, see our related analysis on apparent violation assessment under EU sanctions.
One further cross-border dimension deserves attention: if the business is US-incorporated or has US-person personnel involved in the transaction under review, an OFSI information request may be accompanied by – or may itself trigger – scrutiny from OFAC. The two regulators do not have a formal information-sharing agreement in the public domain, but co-ordination between the UK and US sanctions authorities on enforcement matters is a recognised feature of the current environment. Manage both processes in parallel from the outset.
For businesses with operations or counterparties in Switzerland or Singapore, the comparable information-gathering powers under those regimes also carry strict accuracy obligations and short response windows. We have prepared dedicated practitioner guides for those jurisdictions: see our guide to responding to information requests under SECO and our guide to responding to information requests under Singapore's sanctions regime.
Risk flags and when to involve counsel
Not every OFSI information request requires the same level of external legal support. But several indicators reliably signal that specialist counsel should be involved from the outset, not after the response has been submitted.
Involve counsel immediately if: the request explicitly names your firm as a subject of an investigation, rather than as a holder of relevant information; the underlying transaction involved assets that may have been frozen at the point of the transaction; the request covers activity by individuals at the firm rather than the firm's systems and controls; or the scope of the request is unusually wide, covering multiple counterparties, extended time periods, or multiple business lines. These patterns suggest that OFSI's enquiry is more advanced than the initial request indicates.
Also involve counsel if the documents within scope include any communications that might be read as indicating awareness of sanctions risk before the transaction was executed. An internal email asking whether a counterparty was subject to sanctions, received before the transaction and not acted upon, is exactly the kind of document that shifts the enforcement analysis from a technical breach to a wilful or reckless violation. That distinction carries significant consequences for the penalty level and for the possibility of a settlement.
The position above covers the standard procedural case. Your specific facts – the counterparty, the transaction structure, the regime in play, and the documentation that exists – change the analysis and the strategy. Contact Calder & Vance at info@caldervance.com for a confidential assessment of your exposure and an early-stage review of the response strategy.
A common myth: the information request is just a formality
A significant number of businesses that approach us after receiving an OFSI information request tell us that their initial reaction was that the request was routine – a box-ticking exercise that internal compliance could handle without external advice. That assumption is, in our experience, the single most reliable predictor of a poor outcome.
OFSI's information requests are designed to generate the evidence base for enforcement decisions. The agency has clear statutory authority to use the information gathered in a response to impose a civil monetary penalty, to issue a public disclosure, or – in cases involving wilful violations – to refer the matter to the Crown Prosecution Service. These are not theoretical outcomes: OFSI has exercised all of these powers in recent enforcement cycles.
Treating the response as a formality leads firms to provide incomplete documents, to draft explanatory narratives without proper review, and to miss the window for a voluntary self-disclosure that might have reduced the penalty. The time cost of doing the first response correctly is far lower than the cost of correcting it – because in most cases, the correction comes too late.
If a transaction has already been flagged, or if the information request is the first indication that a breach may have occurred, an early review preserves options that narrow quickly. Contact us at info@caldervance.com to discuss next steps.
Related practices
- Apparent violation assessment – EU sanctions – assessing exposure and response options under EU regime enforcement frameworks
- Responding to regulator information requests – SECO – step-by-step guide for Swiss sanctions information demands
- Responding to regulator information requests – Singapore – practitioner guide for Singapore sanctions regime enquiries